Category: Vulnerabilities
Android 17 Bakes In Encrypted Client Hello to Stop ISP Snooping
Google's Android 17 adds OS-level support for Encrypted Client Hello, hiding visited domain names from network providers by default, alongside stricter local…
Windows 11 KB5120998 Preview Update Brings 35 Fixes, New Admin Protection Feature
Microsoft's August 2026 optional cumulative update for Windows 11 24H2 and 25H2 adds taskbar and Start menu customization, begins rollout of a…
PaperCut Zero-Day Under Active Exploitation, Hits All NG and MF Versions
PaperCut has confirmed active zero-day attacks against all versions of its NG and MF print management software, releasing emergency patches while urging…
Trump Order Bans Foreign-Made Bulk-Power Equipment Over Backdoor Fears
A new executive order blocks acquisition of foreign-made technology used to run the U.S. power grid, citing rising cyber threats and supply-chain…
Boston Scientific Cyberattack Disrupts Order Processing and Shipments
The medical device maker disclosed a cybersecurity incident to the SEC that has knocked out access to key operating systems, halting its…
Critical Avada WordPress Theme Flaw Chains Six Bugs Into Zero-Click RCE
A critical vulnerability chain in the Avada theme and Fusion Builder plugin lets unauthenticated attackers achieve full server compromise, though exploitation requires…
Nutex Health Discloses Network Breach, Patient Data at Risk
The Houston-based hospital operator says attackers accessed and exfiltrated files from some of its servers, and warns the stolen data could be…
Chrome 152 Fixes Over 300 Bugs, Most Found by Google’s AI Tools
Google's latest Chrome release patches 327 vulnerabilities, including 10 critical use-after-free flaws, with the vast majority uncovered internally through AI-assisted vulnerability research.
WhatsApp Rolls Out Multiple Passkeys and Stronger Two-Step Verification
Meta is expanding WhatsApp's account security with support for multiple passkeys across iOS and Android, alphanumeric two-step verification passwords, and added context…
Silent Patches Don’t Stop Attackers, They Just Blind Defenders
A SecurityWeek analysis argues that vendors who quietly fix vulnerabilities without CVEs or advisories aren't protecting users, they're just leaving IT teams…
Attackers Chain miniOrange SAML Bugs for WordPress Admin Takeover
Two unauthenticated auth bypass flaws in the Xecurify miniOrange SAML SSO plugin are being actively exploited to forge signatures and hijack WordPress…
Unpatched Calix Router Flaw Lets Anyone Punch Holes Through NAT
An unauthenticated UPnP exposure in Calix GS7 XGS gateways lets remote attackers create persistent port-forwarding rules that expose cameras, NAS boxes, and…